Skip to content
Legal

Security at Otaly

How we protect your events, your attendees, and their data.

Last updated: 2026

Our approach

Security is built into how we operate Otaly. We protect host and attendee data with layered safeguards and review our practices as the platform grows.

Data protection

Traffic to Otaly is encrypted in transit with TLS. Sensitive data is protected at rest, and access to production systems is restricted to authorized personnel on a need-to-know basis.

Payments

Card payments are handled by PCI-DSS-compliant third-party payment providers. Otaly does not store full card numbers; we receive only the limited transaction data needed to run ticketing and payouts.

Infrastructure & access

Otaly runs on reputable cloud infrastructure with isolation between environments. We apply least-privilege access controls, authentication safeguards, and monitoring to detect and respond to abuse.

Responsible disclosure

If you believe you have found a security vulnerability, we want to hear from you. Please report it privately through our contact channel and give us a reasonable opportunity to investigate and remediate before any public disclosure. We do not pursue good-faith researchers who follow responsible disclosure.

Machine-readable contact details are published at /.well-known/security.txt.

Report a vulnerability

Reach our security team through the contact page.